Russian IT firms, particularly those contracted by the government, have been subjected to a stealthy wave of attacks from Chinese state-backed advanced persistent threat operation APT31 since last year, The Hacker News reports.Intrusions launched by APT31, also known as Violet Typhoon, Judgment Panda, and PerplexedGoblin, involved multiple tools, including legitimate cloud services, such as Yandex Cloud, for command-and-control, the SharpADUserIP utility for reconnaissance, and SharpChrome.exe for browser cookie and credential compromise, according to an analysis from Positive Technologies.APT31 also harnessed Microsoft dev tunnels, the Tailscale VPN, the SharpDir file-searching tool, and the Owawa credential-stealing IIS module, as well as the OneDriveDoor and CloudSorcerer backdoors that leveraged OneDrive and cloud services as C2, respectively. Additional payloads have also been distributed by APT31 through the COFFProxy backdoor, while the LocalPlugX malware enabled local network infections."APT31 is constantly replenishing its arsenal: although they continue to use some of their old tools... These tools and techniques allowed APT31 to stay unnoticed in the infrastructure of victims for years," said researchers.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




